Skip to content
E
ERPResearch
CheckAud logo

CheckAud

by IBS Schreiber GmbH · Access Controls & SoD

SAP authorization and SoD audit software analyzing exported system data for compliance risk.

Updated August 2026 · By the ERP Research Editorial Team · Independent and vendor-neutral.

Works with
SAP
Company size
Mid-market, Enterprise
Pricing
Tiered: free assessment, fixed-fee proof of concept, quote-based license
Founded
1979
Headquarters
Hamburg, Germany

Overview

CheckAud is an SAP authorization and compliance-audit tool developed by IBS Schreiber GmbH, a Hamburg, Germany-based SAP security specialist founded in 1979. It analyzes data exported from SAP ECC and S/4HANA systems to identify segregation-of-duties (SoD) conflicts, excessive permissions, and configuration/parameter risks, without requiring an add-on installed inside the production system.

The product organizes analysis into can-do checks (what a user is authorized to do), did-do checks (what a user actually did, drawn from log data), and parameter checks (system configuration risk), each scored for risk severity. Reports are built to align with IDW PS 880, the German standard for software-supported audits, and the tool includes reference rule sets addressing DSAG, GDPR and SOX-relevant controls. It supports multi-client and multi-system analysis for organizations auditing several SAP instances at once, including authorization clean-up ahead of SAP S/4HANA migrations.

CheckAud is positioned as a detective control that complements preventive SAP GRC access-control systems by monitoring what is actually configured and used in a live system, rather than only what is approved at role-creation time. IBS Schreiber also offers related SAP security consulting, the CASA (Certified Auditor for SAP Applications) training program developed with ISACA, and a companion product, Easy Content Solution (ECS).

Screenshots & demo

Demo video from the vendor's YouTube channel.

Features & capabilities

Authorization & SoD Analysis

Automated analysis of SAP roles and authorizations for conflicts and excess access.

  • Segregation-of-duties (SoD) conflict detection with risk scoring
  • Can-Do analysis of excessive or unused permissions
  • Did-Do analysis of actual user activity from system logs
  • Field-level authorization checks across SAP modules
  • Critical parameter and system-configuration checks
  • Support for custom and IBS Schreiber-supplied risk rule sets

Multi-System & Migration Support

Cross-landscape analysis and migration readiness.

  • Multi-client and multi-system (cross-landscape) analysis
  • SAP S/4HANA migration authorization validation
  • Role-concept clean-up ahead of migration
  • International, group-wide rollout support

Compliance & Reporting

Audit-ready reporting aligned to recognized standards.

  • Audit-ready reports generated automatically
  • IDW PS 880-aligned audit methodology
  • Reference rule sets covering DSAG, GDPR and SOX-relevant controls
  • Management-level risk dashboards and prioritized findings
  • Continuous, recurring compliance-monitoring option

Deployment & Integration

Lightweight deployment model built around exported system data.

  • Plug-and-play deployment using exported SAP data
  • No modification to the production SAP system
  • Interfaces for data export and system-to-system comparison
  • Complements SAP GRC Access Control and IDM processes as a detective layer

Common use cases

  • Preparing for external or internal SAP authorization audits with IDW PS 880-aligned reporting
  • Detecting segregation-of-duties conflicts across SAP ECC or S/4HANA roles
  • Cleaning up excessive or unused permissions before an S/4HANA migration
  • Running continuous, detective monitoring of SAP authorizations alongside a preventive GRC tool
  • Comparing authorizations and configuration across multiple SAP clients or systems in a group structure
  • Producing audit-ready evidence for SOX or GDPR-relevant access controls
  • Replacing manual, spreadsheet-based SAP authorization reviews

Strengths & considerations

Strengths

  • Analyzes exported SAP data rather than requiring an add-on installed inside the production system
  • Purpose-built for IDW PS 880-compliant audit reporting, developed by an SAP security specialist operating since 1979
  • Positioned as a detective control that complements, rather than replaces, preventive SAP GRC Access Control systems
  • Maintained risk rule set library addressing DSAG, GDPR and SOX-relevant frameworks

ERP integrations

Data export / offline analysisERP -> product

Analyzes data exported from SAP ECC and S/4HANA systems; no installation inside the production system required

Pricing

Model
Tiered: free assessment, fixed-fee proof of concept, quote-based license
Starting price
EUR 1,490 for a 30-day Proof of Concept license including workshop
Free trial
Yes

Free one-time Security Check assessment; 30-day Proof of Concept license is a fixed EUR 1,490 fee including a workshop; ongoing Company License for continuous, multi-system compliance is quote-based. Get an independent shortlist with pricing guidance below.

Technical & security

Compliance
IDW PS 880
Languages
German, English

About the vendor

Founded
1979
Headquarters
Hamburg, Germany
Ownership
Private (GmbH)
Notable customers
Caterpillar, JOST-Werke

Alternatives to CheckAud in Access Controls & SoD

CheckAud — frequently asked questions

How is CheckAud different from an SAP GRC system?

CheckAud complements preventive SAP GRC systems, which check authorizations at role-creation time, with detective analysis of the live system as actually configured. It surfaces risks that a preventive, role-design-only check would not catch.

Does CheckAud replace manual SAP authorization reviews?

IBS Schreiber positions CheckAud as an automation layer for manual, spreadsheet-based authorization reviews, citing time savings of up to 80 percent compared with manual analysis, plus objective, repeatable risk scoring.

Does CheckAud support SAP S/4HANA migration projects?

Yes. CheckAud is used to clean up critical authorizations and avoid carrying forward segregation-of-duties conflicts as organizations migrate from SAP ECC to S/4HANA.

Can CheckAud analyze multiple SAP systems or clients at once?

Yes. CheckAud is built for multi-client and multi-system (cross-landscape) scenarios, supporting organizations that need to compare authorizations and risk across several SAP instances.

What audit standard does CheckAud's reporting follow?

CheckAud generates reports aligned to IDW PS 880, the German standard for software-supported audits, and includes reference rule sets addressing DSAG, GDPR and SOX-relevant controls.

Evaluating Access Controls & SoD?

Tell us your ERP and requirements and we'll send an independent shortlist — including CheckAud and the best-fit alternatives — with honest pros and cons.

By submitting, you agree that ERP Research may share your details with matched ERP implementation partners, who may contact you about your enquiry. Privacy policy

Join 2,000+ companies using ERP Research to find their ideal ERP